Branch was auto-updated.

This commit is contained in:
srv-rr-gh-researchbt
2023-02-06 16:01:21 -08:00
committed by GitHub
4 changed files with 112 additions and 0 deletions
@@ -0,0 +1,75 @@
name: Windows Data Destruction Recursive Exec Files Deletion
id: 3596a799-6320-4a2f-8772-a9e98ddb2960
version: 1
date: '2023-02-02'
author: Teoderick Contreras, Splunk
type: TTP
datamodel:
- Endpoint
description: The following analytic identifies a suspicious process recursively deleting files in a compromised host.
This behavior was seen in several destructive malware, wiper like caddy wiper, doublezero, and now swiftslicer that delete or
overwrite files with random generated strings to make it unrecoverable. This analytic can also catch a possible recursive file write on multiple files
using Sysmon Event 23. Sysmon treats the modified file as a deleted one as soon as it was overwritten. This analytic can be a good indicator that a possible
destructive malware is running in a host machine or a big software application is being uninstalled.
search: '`sysmon` EventCode=23 TargetFilename IN ("*.exe", "*.sys", "*.dll")
| bin _time span=2m
| stats values(TargetFilename) as deleted_files min(_time) as firstTime max(_time) as lastTime count by Computer user EventCode Image ProcessID
| where count >=500
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
| `windows_data_destruction_recursive_exec_files_deletion_filter`'
how_to_implement: To successfully implement this search, you need to be ingesting
logs with the deleted target file name, process name and process id from your endpoints.
If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA.
known_false_positives: uninstall a big software application may trigger this detection. Filter is needed.
references:
- https://www.welivesecurity.com/2023/01/27/swiftslicer-new-destructive-wiper-malware-ukraine/
tags:
analytic_story:
- Swift Slicer
asset_type: Endpoint
cis20:
- CIS 3
- CIS 5
- CIS 16
confidence: 80
context:
- Source:Endpoint
- Stage:Execution
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/swift_slicer/sysmon.log
impact: 80
kill_chain_phases:
- Exploitation
message: a big number of executable files being deleted in $Computer$
mitre_attack_id:
- T1485
nist:
- DE.CM
observable:
- name: user
type: User
role:
- Victim
- name: Computer
type: Endpoint
role:
- Victim
- name: deleted_files
type: File Name
role:
- Target
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- EventCode
- TargetFilename
- Computer
- user
- Image
- ProcessID
- _time
risk_score: 64
security_domain: endpoint
@@ -30,6 +30,7 @@ tags:
- Clop Ransomware
- WhisperGate
- DarkCrystal RAT
- Swift Slicer
confidence: 80
context:
- Source:Endpoint
+23
View File
@@ -0,0 +1,23 @@
name: Swift Slicer
id: 234c9dd7-52fb-4d6f-aec9-075ef88a2cea
version: 1
date: '2023-02-01'
author: Teoderick Contreras, Rod Soto, Splunk
description: Leverage searches that allow you to detect and investigate unusual activities
that might relate to the swift slicer malware including overwriting of files and etc.
narrative: Swift Slicer is one of Windows destructive malware found by ESET that was used in a targeted organizarion to wipe critical files like windows drivers and other files
to destroy and left the machine inoperable. This malware like Caddy Wiper was deliver through GPO which suggests that the attacker had taken control of the victims active directory environment.
references:
- https://twitter.com/ESETresearch/status/1618960022150729728
- https://www.welivesecurity.com/2023/01/27/swiftslicer-new-destructive-wiper-malware-ukraine/
tags:
analytic_story: Swift Slicer
category:
- Data Destruction
- Malware
- Adversary Tactics
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
usecase: Advanced Threat Detection
@@ -0,0 +1,13 @@
name: Windows Data Destruction Recursive Exec Files Deletion Unit Test
tests:
- name: Windows Data Destruction Recursive Exec Files Deletion
file: endpoint/windows_data_destruction_recursive_exec_files_deletion.yml
pass_condition: '| stats count | where count > 0'
earliest_time: -24h
latest_time: now
attack_data:
- file_name: sysmon.log
data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/swift_slicer/sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
update_timestamp: true